Impact
A vulnerability in the Endeca Application Controller component of Oracle Commerce Guided Search allows an attacker who has already logged on to the infrastructure on which the application runs to compromise the software. The flaw can be exploited from a low‑privileged account, permitting the attacker to execute actions with the same permissions as those of the application, effectively taking control of the Commerce Guided Search service. The impact is a full compromise of confidentiality, integrity, and availability for all data and services managed by the application.
Affected Systems
Oracle Corporation’s Oracle Commerce Guided Search / Oracle Commerce Experience Manager version 11.4.0 is affected. Only this version is specified as vulnerable; no other versions or build numbers are listed.
Risk and Exploitability
The vulnerability has a CVSS 3.1 base score of 7.8 with local attack, low authentication, and no user interaction required. The EPSS score is 0.00151, indicating a very low probability of exploitation. The issue is not listed in the CISA KEV catalog. Because an attacker only needs local access, the risk is significant for any environment where low‑privileged accounts have shell or system access. Exploitation does not require network exposure beyond the local system, making it likely to be used by internal adversaries or attackers who have gained foothold on the host.
OpenCVE Enrichment